Skip to content
Siyah.

Legal / Siyah

Privacy Policy

This policy explains what information this website and the Shopify tracking migration service handle, why it is used, and the providers involved.

Last updated: August 18, 2026

1. Who this policy covers

This policy applies to siyahco.com and the technical services offered by Siyah (“Siyah,” “we,” or “us”). Siyah is a small technical service business. This policy does not describe the independent practices of a Shopify merchant, agency, advertising platform, or other third party.

2. Information you provide

Free tracking checks

The free tracking-check form asks for your name, business email, agency or company, Shopify store URL, whether you are an agency or merchant, and optional information about tracking tools, concerns, and Shopify upgrade-report findings.

Paid project intake

The migration intake asks for your name, work email, agency or company, Shopify store URL, buyer type, tracking integrations, and whether white-label delivery is requested. You may optionally provide a project identifier and a short technical concern.

Email and project communication

If you email us or proceed with a project, we handle the information in your message and the project information, access instructions, and QA material needed to perform the service. Do not send passwords, API secrets, advertising-account credentials, card information, or unnecessary customer personal information through forms or email.

3. Checkout and payment information

Dodo Payments hosts and processes checkout for the paid service. We send Dodo Payments the checkout customer name and email plus non-sensitive project metadata such as company, store URL, selected integrations, white-label preference, project notes, and outreach attribution when supplied.

We use Dodo Payments’ server-side API and signed webhooks to create the checkout and verify payment status. Dodo Payments can return identifiers, payment status, checkout email, and submitted metadata to us for those purposes. Siyah does not directly collect or store card numbers in this website or an application database. Payment information is handled under the Dodo Payments privacy policy.

4. Outreach attribution and browser storage

When present in an arrival URL, the site reads `utm_source`, `utm_medium`, `utm_campaign`, `utm_content`, and `ref`. These values are kept in browser session storage so they can be attached to a checkout or free tracking-check request. Session storage is controlled by your browser and generally lasts for the browser tab or session.

The site also uses a session-storage key to avoid counting the same checkout-return or verified-payment event repeatedly in one browser session. That local key can include the Dodo payment reference, but the reference is not sent as a Google Analytics event parameter. It does not contain form fields or card information.

5. Optional analytics

If a Google Analytics 4 measurement ID is configured, the site loads one Google Analytics tag and sends limited conversion events, such as an offer view, call-to-action click, submitted free check, checkout creation, checkout return, and verified payment.

Analytics and advertising storage are configured as denied, advertising signals and personalization are disabled, and page URLs are sanitized. Normal pages expose only the approved UTM/ref parameters; the payment return page excludes its checkout query parameters. We do not put names, emails, store details, customer notes, or payment identifiers in GA event parameters. Google can still process limited browser, device, network, and measurement information in connection with cookieless analytics requests under the Google Privacy Policy. If no measurement ID is configured, the analytics tag does not load.

6. How we use information

  • Respond to inquiries and assess free tracking-check requests.
  • Create checkout sessions and confirm payment.
  • Scope, perform, test, document, and support the agreed service.
  • Communicate with the customer or the authorized agency contact.
  • Understand which outreach and service actions lead to inquiries or purchases.
  • Protect the forms, diagnose errors, and maintain site reliability.
  • Maintain appropriate transaction and project records.

7. Service providers and disclosure

Information is shared only as needed to operate and deliver the service:

  • Dodo Payments for hosted checkout, payment processing, transaction records, and payment verification.
  • Resend, when configured, to deliver free tracking-check form contents to our internal contact address. See the Resend Privacy Policy.
  • Google Analytics, only when configured, for the limited measurement described above.
  • Hosting and infrastructure providers that process ordinary request, security, and diagnostic information needed to operate the website.
  • Shopify, Google, Meta, TikTok, affiliate, or other project platforms when you authorize access or ask us to configure and verify them.

We do not sell personal information. We may disclose information when required by law, to protect rights or security, or with your direction.

8. Storage and retention

The current website does not use an application database for contact leads or project intake. That does not mean submitted information is never stored: it can remain in internal email, Dodo Payments transaction data and metadata, limited server/hosting logs, and project files created while delivering the work.

We keep information only for as long as reasonably needed to respond, deliver and support the service, maintain transaction and QA records, resolve disputes, and meet applicable obligations. Third-party providers apply their own retention practices. We minimize or remove project access and unnecessary customer information after the work is complete.

9. Security and access

We use server-side payment credentials and, when email delivery is configured, server-side email credentials. We also use signed webhook verification, input validation, and role-based Shopify/platform access where available. No internet service is completely secure, but we limit the information collected and prefer named collaborator or staff access with only the permissions required. Never send us passwords or card information.

10. Your choices and requests

You can choose not to submit optional information or not to proceed with checkout. You can clear session storage using your browser controls. You may contact us to ask about, correct, or request deletion of information you submitted. Some information might need to be retained for transaction, legal, security, or project-record purposes, and provider-held information can be subject to the provider’s process.

11. Changes and contact

We may update this policy when the site, providers, or service changes. The current version and update date will remain on this page.

For privacy questions or requests, email aswadi.bit@gmail.com.